Sophos

OSX/Hovdy-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Macintosh
Included in our products from August 2008 (4.32)
Protection available since 23 June 2008 05:41:04 (GMT)
Last updated 23 June 2008 15:59:22 (GMT)
Detected by All Sophos products

Action

More Information

OSX/Hovdy-A is a Trojan for the Mac OS X platform.

When run the Trojan will attempt to install itself to the /Library/Caches folder and perform the following tasks:

  - disable system logging and delete system log files
  - start PHPShell and web server
  - start ARD, VNC and SSH services
  - disable system updates
  - open ports in the firewall
  - disable third party security software
  - install LogKext keylogger
  - steal various password hashes and keys which may be used to compromise other systems

OSX/Hovdy-A will also attempt to use the ARDAgent vulnerability to obtain root access.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer